VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 107 of 350
  • CVE-2023-36718HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability

  • CVE-2023-36702HigOct 10, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft DirectMusic Remote Code Execution Vulnerability

  • CVE-2023-41444HigSep 28, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver.

  • CVE-2023-41984HigSep 27, 2023
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-34195HigSep 18, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage method retrieves the value of a runtime variable named GetImageProgress, and later uses this value as a function pointer. This…

  • CVE-2023-41005HigAug 28, 2023
    risk 0.51cvss 7.8epss 0.01

    An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php

  • CVE-2023-33469HigAug 9, 2023
    risk 0.51cvss 7.8epss 0.00

    In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.

  • CVE-2023-36923HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.00

    SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the behavior of the application.

  • CVE-2023-32418HigJul 27, 2023
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. Processing a file may lead to unexpected app termination or arbitrary code execution.

  • CVE-2023-34448HigJun 14, 2023
    risk 0.51cvss 8.8epss 0.05

    Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that…

  • CVE-2023-1049HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.

  • CVE-2019-16283HigJun 9, 2023
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.

  • CVE-2023-33733HigJun 5, 2023
    risk 0.51cvss 7.8epss 0.02

    Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.

  • CVE-2023-27744HigJun 2, 2023
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in South River Technologies TitanFTP NextGen server that allows for a vertical privilege escalation leading to remote code execution.

  • CVE-2022-35743HigMay 31, 2023
    risk 0.51cvss 7.8epss 0.01

    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

  • CVE-2023-33440HigMay 26, 2023
    risk 0.51cvss 7.2epss 0.15

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.

  • CVE-2023-27770HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in Wondershare Technology Co.,Ltd Edraw-max v.12.0.4 allows a remote attacker to execute arbitrary commands via the edraw-max_setup_full5371.exe file.

  • CVE-2022-38745HigMar 24, 2023
    risk 0.51cvss 7.8epss 0.01

    Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

  • CVE-2023-0598HigMar 16, 2023
    risk 0.51cvss 7.8epss 0.01

    GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path and gain full control of the HMI…

  • CVE-2023-27986HigMar 9, 2023
    risk 0.51cvss 7.8epss 0.00

    emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.